Legal
Sub-processors
Last updated 18 May 2026 · referenced by the Data processing addendum
1. Live list
These are the vendors that may process personal data on behalf of AuthorityOn AI customers. Each is bound by a Data Processing Agreement at least as protective as the GDPR Article 28 baseline.
| Vendor | Purpose | Location | Transfer basis |
|---|---|---|---|
| Vercel Inc. | Hosting and edge delivery of the web application. | EU region (Frankfurt) + global edge. | SCCs (Module 2) with EU-region pinning of compute and storage where supported. |
| Supabase Inc. | Primary database (Postgres), authentication helper. | EU region (Frankfurt). | Region-pinned within EU; SCCs in place at the Supabase parent layer. |
| Stripe Payments Europe Ltd. | Payment processing, subscription management, customer portal, invoicing. | EU/Ireland, with global payment-network reach. | Adequacy decision (Ireland) + SCCs for any onward processing. |
| Resend Inc. | Transactional email delivery (magic links, password reset, scan-complete notifications, billing receipts). | US (delivery via global SMTP infra). | EU SCCs (Module 2) signed via Resend DPA. |
| Anthropic, PBC. | LLM API (Claude family) for AI-visibility scans and the recommendation validator. | US. | SCCs; payload limited to scan prompts and validator inputs. No account-identifying metadata sent to the model. |
| OpenAI, LLC. | LLM API (GPT family) for AI-visibility scans. | US. | SCCs; zero-data-retention enabled on the API endpoints we call. Payload limited to scan prompts. |
| Google LLC (Gemini API). | LLM API (Gemini family) for AI-visibility scans. | US. | EU-US Data Privacy Framework + SCCs. Payload limited to scan prompts. |
| xAI Corp. | LLM API (Grok family) for AI-visibility scans. | US. | SCCs. Payload limited to scan prompts. |
| Perplexity AI Inc. | LLM API for AI-visibility scans. | US. | SCCs. Payload limited to scan prompts. |
| Mistral AI SAS. | LLM API for AI-visibility scans. | EU (France). | Intra-EU. No third-country transfer. |
2. Change log
Material changes (additions, removals, or scope changes) are posted here. We give at least 14 days' notice before adding a new sub-processor.
- 2026-05-18 · Initial published list. Carried over from /privacy §6; structured here so future additions are notified and tracked.
3. Subscribe to changes
To receive change notifications by email, write to privacy@authorityon.ai with the addresses you want subscribed. Customers on the Agency tier are subscribed automatically on the contracting contact.
AuthorityOn AI · Sub-processor list v1 · 18 May 2026